Tower procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| Data retention | All applicable tiers | unknown | “ Tower retains personal data we collect from you where we have an ongoing legitimate interest to do so. When personal data is no longer necessary or relevant for the stated purpose or to fulfill a legal or business requirement, it shall be securely destroyed. Tower will either physically or electronically erase the personal data. When processing in our role as a processor, we will retain personal data for as long as our customer instructs us to and/or as required by applicable law.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ When we disclose your personal data for a business purpose, we enter a contract that requires that all third-party processors process your personal data with the same level of protection and in a manner consistent with the uses agreed upon in this Privacy Policy. Tower does not sell your personal data.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Tower may disclose your personal data to various third-party service providers for the following business purposes: To support our information technology; For customer service and account management; To supplement, update, or correct the data or provide additional publicly available data; To manage mailings on our behalf; To aggregate data collected through our Online Services and Website; To perform back-end services related to our Online Services; To perform customer surveys and call recording; To assist with direct marketing efforts; To personalize your Website or Online Service experience; To facilitate marketing events and customer surveys; Where necessary in the course of the professional services that professional advisors such as lawyers, bankers, auditors, and insurers provide to us; To prevent fraud, money laundering, undertake credit checks, comply with laws and check with identity verification agencies; To process an order, issue invoices, take payment from, make payment to your organization, or manage account or payment history; and In the event of a corporate sale, merger, reorganization, dissolution or similar event, your personal data may be part of an asset transfer or sale. We may transfer your personal data to any third party who is not otherwise covered by the categories listed above where you have given us permission to do so, or with whom you have entered into a contract when we need to transfer your personal data to that party in order to fulfil that contract. ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We may share your personal data with other companies within our group of companies in order to use your personal data under these limited circumstances:” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ If your organization's administrator enables it, you may connect Tower to a third-party application, such as an AI assistant, using your Tower credentials. The connected application can access only the Data Rooms and documents your Tower permissions already allow. Information it retrieves at your request is sent to that application and is then governed by that provider's terms and privacy policy, not this Privacy Policy. You can disconnect at any time from within the connected application, and your administrator can disable integrations for your organization.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ From time to time, we may obtain information about you from third-party sources, such as public databases and websites, resellers and distributors, joint marketing or business partners, security and fraud detection firms and social media platforms. Examples of the information we may receive from other sources include contact information from business partners with whom we operate co-branded events, services, and marketing campaigns.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ "Non-Tower Application" means Third Party Products as defined in the Cloud Service Agreement and includes any web-based, mobile, offline or other software functionality that interoperates with a Data Room, that is provided by Customer, User or a third party.” | Captured 2026-09-25Open source →Finding permalink → |
| Tier differences | All applicable tiers | medium | “ You understand that you are being permitted to use the Data Room because you are either: (a) an employee or representative of a customer (the "Customer") which has entered into an agreement with Tower (the "Cloud Service Agreement") to use the Data Room for the Customer's internal business purposes including in connection with a financing, merger, acquisition, sale, or similar corporate transaction (a "Transaction") (such User, a "Customer Employee User"); (b) a client or advisor of the Customer and your respective employee or representative who has been granted access to the Data Room by the Customer or its Customer Employee User (such User, a "Customer Authorized User" and together with Customer Employee Users, "Customer Users"); or (c) a person who is granted access to a specific Data Room for the purpose of conducting due diligence in connection with a potential Transaction, including but not limited to an advisor of a Customer Authorized User, potential buyer, investor, lender or a respective advisor or representative of the same (such User, a "Counterparty User"). To the extent they do not contradict these Terms, your use of the Data Room is also subject to the Cloud Service Agreement (if you are an Customer Employee User) or other Users, any applicable supplemental terms and conditions entered into with Customer ("Customer Terms") and these Terms do not alter in any way the terms or conditions of any agreements you may have with the Customer with respect to your work and services to Customer, including the Customer Terms. ” | Captured 2026-09-25Open source →Finding permalink → |
| Tier differences | All applicable tiers | unknown | “ Customer Employee Users will have full access rights as granted within the scope of the applicable Cloud Service Agreement, including the authority to manage Data Room settings and user permissions. Counterparty Users and Customer Authorized Users will have strictly limited access rights as defined and configured by Customer Employee Users, and may only access Data Rooms to which they have been explicitly invited, and may not grant access to additional users. Counterparty Users and Customer Authorized Users' rights to invite other Users, view, download, copy, or distribute materials are limited to those permissions explicitly granted by Customer Employee Users for each Data Room.” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.